CVE-2025-22037

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-22037
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-22037.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-22037
Downstream
Published
2025-04-16T14:11:55Z
Modified
2025-10-30T23:00:15.914870Z
Summary
ksmbd: fix null pointer dereference in alloc_preauth_hash()
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix null pointer dereference in allocpreauthhash()

The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauthinfo is not allocated. This patch add KSMBDSESSNEEDSETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
cce57cd8c5dead24127cf2308fdd60fcad2d6ba6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
b8eb243e670ecf30e91524dd12f7260dac07d335
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780

Affected versions

v5.*

v5.13
v5.13-rc2
v5.13-rc3
v5.13-rc4
v5.13-rc5
v5.13-rc6
v5.13-rc7
v5.14
v5.14-rc1
v5.14-rc2
v5.14-rc3
v5.14-rc4
v5.14-rc5
v5.14-rc6
v5.14-rc7
v5.15
v5.15-rc1
v5.15-rc2
v5.15-rc3
v5.15-rc4
v5.15-rc5
v5.15-rc6
v5.15-rc7
v5.16
v5.16-rc1
v5.16-rc2
v5.16-rc3
v5.16-rc4
v5.16-rc5
v5.16-rc6
v5.16-rc7
v5.16-rc8
v5.17
v5.17-rc1
v5.17-rc2
v5.17-rc3
v5.17-rc4
v5.17-rc5
v5.17-rc6
v5.17-rc7
v5.17-rc8
v5.18
v5.18-rc1
v5.18-rc2
v5.18-rc3
v5.18-rc4
v5.18-rc5
v5.18-rc6
v5.18-rc7
v5.19
v5.19-rc1
v5.19-rc2
v5.19-rc3
v5.19-rc4
v5.19-rc5
v5.19-rc6
v5.19-rc7
v5.19-rc8

v6.*

v6.0
v6.0-rc1
v6.0-rc2
v6.0-rc3
v6.0-rc4
v6.0-rc5
v6.0-rc6
v6.0-rc7
v6.1
v6.1-rc1
v6.1-rc2
v6.1-rc3
v6.1-rc4
v6.1-rc5
v6.1-rc6
v6.1-rc7
v6.1-rc8
v6.10
v6.10-rc1
v6.10-rc2
v6.10-rc3
v6.10-rc4
v6.10-rc5
v6.10-rc6
v6.10-rc7
v6.11
v6.11-rc1
v6.11-rc2
v6.11-rc3
v6.11-rc4
v6.11-rc5
v6.11-rc6
v6.11-rc7
v6.12
v6.12-rc1
v6.12-rc2
v6.12-rc3
v6.12-rc4
v6.12-rc5
v6.12-rc6
v6.12-rc7
v6.12.1
v6.12.10
v6.12.11
v6.12.12
v6.12.13
v6.12.14
v6.12.15
v6.12.16
v6.12.17
v6.12.18
v6.12.19
v6.12.2
v6.12.20
v6.12.21
v6.12.22
v6.12.3
v6.12.4
v6.12.5
v6.12.6
v6.12.7
v6.12.8
v6.12.9
v6.13
v6.13-rc1
v6.13-rc2
v6.13-rc3
v6.13-rc4
v6.13-rc5
v6.13-rc6
v6.13-rc7
v6.13.1
v6.13.10
v6.13.2
v6.13.3
v6.13.4
v6.13.5
v6.13.6
v6.13.7
v6.13.8
v6.13.9
v6.14
v6.14-rc1
v6.14-rc2
v6.14-rc3
v6.14-rc4
v6.14-rc5
v6.14-rc6
v6.14-rc7
v6.14.1
v6.2
v6.2-rc1
v6.2-rc2
v6.2-rc3
v6.2-rc4
v6.2-rc5
v6.2-rc6
v6.2-rc7
v6.2-rc8
v6.3
v6.3-rc1
v6.3-rc2
v6.3-rc3
v6.3-rc4
v6.3-rc5
v6.3-rc6
v6.3-rc7
v6.4
v6.4-rc1
v6.4-rc2
v6.4-rc3
v6.4-rc4
v6.4-rc5
v6.4-rc6
v6.4-rc7
v6.5
v6.5-rc1
v6.5-rc2
v6.5-rc3
v6.5-rc4
v6.5-rc5
v6.5-rc6
v6.5-rc7
v6.6
v6.6-rc1
v6.6-rc2
v6.6-rc3
v6.6-rc4
v6.6-rc5
v6.6-rc6
v6.6-rc7
v6.6.1
v6.6.10
v6.6.100
v6.6.101
v6.6.102
v6.6.103
v6.6.104
v6.6.105
v6.6.106
v6.6.11
v6.6.12
v6.6.13
v6.6.14
v6.6.15
v6.6.16
v6.6.17
v6.6.18
v6.6.19
v6.6.2
v6.6.20
v6.6.21
v6.6.22
v6.6.23
v6.6.24
v6.6.25
v6.6.26
v6.6.27
v6.6.28
v6.6.29
v6.6.3
v6.6.30
v6.6.31
v6.6.32
v6.6.33
v6.6.34
v6.6.35
v6.6.36
v6.6.37
v6.6.38
v6.6.39
v6.6.4
v6.6.40
v6.6.41
v6.6.42
v6.6.43
v6.6.44
v6.6.45
v6.6.46
v6.6.47
v6.6.48
v6.6.49
v6.6.5
v6.6.50
v6.6.51
v6.6.52
v6.6.53
v6.6.54
v6.6.55
v6.6.56
v6.6.57
v6.6.58
v6.6.59
v6.6.6
v6.6.60
v6.6.61
v6.6.62
v6.6.63
v6.6.64
v6.6.65
v6.6.66
v6.6.67
v6.6.68
v6.6.69
v6.6.7
v6.6.70
v6.6.71
v6.6.72
v6.6.73
v6.6.74
v6.6.75
v6.6.76
v6.6.77
v6.6.78
v6.6.79
v6.6.8
v6.6.80
v6.6.81
v6.6.82
v6.6.83
v6.6.84
v6.6.85
v6.6.86
v6.6.87
v6.6.88
v6.6.89
v6.6.9
v6.6.90
v6.6.91
v6.6.92
v6.6.93
v6.6.94
v6.6.95
v6.6.96
v6.6.97
v6.6.98
v6.6.99
v6.7
v6.7-rc1
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.8
v6.8-rc1
v6.8-rc2
v6.8-rc3
v6.8-rc4
v6.8-rc5
v6.8-rc6
v6.8-rc7
v6.9
v6.9-rc1
v6.9-rc2
v6.9-rc3
v6.9-rc4
v6.9-rc5
v6.9-rc6
v6.9-rc7

Database specific

vanir_signatures

[
    {
        "id": "CVE-2025-22037-024ce9b6",
        "digest": {
            "line_hashes": [
                "40640551838881666992412891435356750114",
                "287445069216143970143252157146317153442",
                "272432220197545348692215718554704739346",
                "200796643468251471636356344036150090181",
                "114625347888109672118197518536968378968",
                "158215045584098059507582942883917511226",
                "328299363384410295763884869006539661562",
                "113803501980142141196269119362031329675",
                "244647404035860198967322688899819607806",
                "19240269759446072652502041473946465172"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/connection.h"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cce57cd8c5dead24127cf2308fdd60fcad2d6ba6",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-04cd84ec",
        "digest": {
            "length": 5207.0,
            "function_hash": "51044291861950428742294976349810516179"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_sess_setup"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cce57cd8c5dead24127cf2308fdd60fcad2d6ba6",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-068839a4",
        "digest": {
            "line_hashes": [
                "325448000465391200100892215415955313038",
                "21027551650952136140564420539977572300",
                "318944161087451046256217667886885275348",
                "129819164659489964156793981930181478976",
                "258441204198463208476705604174028848564",
                "247942568155215386677883202851520230913",
                "170526147657533789799389891840977733144",
                "243301067770454264198809896844511470745",
                "81851043980562522459033969244191262560"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-07f17215",
        "digest": {
            "line_hashes": [
                "325448000465391200100892215415955313038",
                "21027551650952136140564420539977572300",
                "318944161087451046256217667886885275348",
                "129819164659489964156793981930181478976",
                "258441204198463208476705604174028848564",
                "247942568155215386677883202851520230913",
                "170526147657533789799389891840977733144",
                "243301067770454264198809896844511470745",
                "81851043980562522459033969244191262560"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-09b7312b",
        "digest": {
            "length": 1181.0,
            "function_hash": "166258855410913138801266803317107526426"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_session_logoff"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8eb243e670ecf30e91524dd12f7260dac07d335",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-0a4a6696",
        "digest": {
            "line_hashes": [
                "325448000465391200100892215415955313038",
                "21027551650952136140564420539977572300",
                "318944161087451046256217667886885275348",
                "129819164659489964156793981930181478976",
                "258441204198463208476705604174028848564",
                "247942568155215386677883202851520230913",
                "170526147657533789799389891840977733144",
                "243301067770454264198809896844511470745",
                "81851043980562522459033969244191262560"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8eb243e670ecf30e91524dd12f7260dac07d335",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-0ddd6001",
        "digest": {
            "line_hashes": [
                "325448000465391200100892215415955313038",
                "21027551650952136140564420539977572300",
                "318944161087451046256217667886885275348",
                "129819164659489964156793981930181478976",
                "258441204198463208476705604174028848564",
                "247942568155215386677883202851520230913",
                "170526147657533789799389891840977733144",
                "243301067770454264198809896844511470745",
                "81851043980562522459033969244191262560"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-126a4c91",
        "digest": {
            "line_hashes": [
                "297004126756288227908285474675522726703",
                "268659658837504198401863032526307706032",
                "51448650403117895317813221185544537069",
                "289873519735553229074859803961269895940",
                "237716553558632709093956764661326776463",
                "130979960009992921730539082423788934756",
                "217046446482590909808361427330581534764",
                "249667312923185645835762253499634725836",
                "335881720498473020984678720935303353685",
                "335590987076451830758487913687396859075",
                "327422833182963144665463407599434122618",
                "54690712854944189062554638213604010981",
                "267450405378082489665943207360784785230",
                "87180532630101454121491995230000699392",
                "195554818792450739061977712802667231779",
                "8404521866083984629593440128119862089",
                "99133310780563828978719478026243020695",
                "294218342844689681484611504057682437036"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/smb2pdu.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cce57cd8c5dead24127cf2308fdd60fcad2d6ba6",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-1e30b209",
        "digest": {
            "length": 294.0,
            "function_hash": "192398793024694815669275777632824046261"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "alloc_preauth_hash"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cce57cd8c5dead24127cf2308fdd60fcad2d6ba6",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-2d18aff7",
        "digest": {
            "length": 294.0,
            "function_hash": "192398793024694815669275777632824046261"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "alloc_preauth_hash"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-4c24eba6",
        "digest": {
            "length": 1181.0,
            "function_hash": "166258855410913138801266803317107526426"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_session_logoff"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-5dac30da",
        "digest": {
            "length": 841.0,
            "function_hash": "34318263936675239701043990964831082586"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c",
            "function": "destroy_previous_session"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cce57cd8c5dead24127cf2308fdd60fcad2d6ba6",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-6494f613",
        "digest": {
            "line_hashes": [
                "297004126756288227908285474675522726703",
                "268659658837504198401863032526307706032",
                "296624723961167180803562079528672614966",
                "305992643832729861349185135912817091989",
                "237716553558632709093956764661326776463",
                "330562563618925551574172467480594720498",
                "283338264937735944827811546257209429354",
                "105309349186937946931560644591162732123",
                "207897301114757964331025186930230631017",
                "188280945983518673268505405196069810786",
                "327422833182963144665463407599434122618",
                "54690712854944189062554638213604010981",
                "267450405378082489665943207360784785230",
                "87180532630101454121491995230000699392",
                "195554818792450739061977712802667231779",
                "8404521866083984629593440128119862089",
                "99133310780563828978719478026243020695",
                "294218342844689681484611504057682437036"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/smb2pdu.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-6ffe6786",
        "digest": {
            "line_hashes": [
                "325448000465391200100892215415955313038",
                "21027551650952136140564420539977572300",
                "318944161087451046256217667886885275348",
                "129819164659489964156793981930181478976",
                "258441204198463208476705604174028848564",
                "247942568155215386677883202851520230913",
                "175447026143323302902636364560442388817",
                "264541093609604709744525843454733088761",
                "339565361653632832701298007524429225103"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cce57cd8c5dead24127cf2308fdd60fcad2d6ba6",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-728b6b62",
        "digest": {
            "length": 5356.0,
            "function_hash": "91678965444341212030254614913153855375"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_sess_setup"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-752c6ad7",
        "digest": {
            "length": 856.0,
            "function_hash": "174818639193327642443409448044413801833"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c",
            "function": "destroy_previous_session"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8eb243e670ecf30e91524dd12f7260dac07d335",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-7b724c72",
        "digest": {
            "line_hashes": [
                "40640551838881666992412891435356750114",
                "287445069216143970143252157146317153442",
                "272432220197545348692215718554704739346",
                "200796643468251471636356344036150090181",
                "114625347888109672118197518536968378968",
                "158215045584098059507582942883917511226",
                "328299363384410295763884869006539661562",
                "113803501980142141196269119362031329675",
                "244647404035860198967322688899819607806",
                "19240269759446072652502041473946465172"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/connection.h"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-82805734",
        "digest": {
            "length": 5356.0,
            "function_hash": "91678965444341212030254614913153855375"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_sess_setup"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8eb243e670ecf30e91524dd12f7260dac07d335",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-90f398e6",
        "digest": {
            "length": 301.0,
            "function_hash": "93556800727486564952528467828972704206"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "alloc_preauth_hash"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8eb243e670ecf30e91524dd12f7260dac07d335",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-943189c5",
        "digest": {
            "length": 856.0,
            "function_hash": "174818639193327642443409448044413801833"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c",
            "function": "destroy_previous_session"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-9463f26a",
        "digest": {
            "line_hashes": [
                "40640551838881666992412891435356750114",
                "287445069216143970143252157146317153442",
                "272432220197545348692215718554704739346",
                "200796643468251471636356344036150090181",
                "114625347888109672118197518536968378968",
                "158215045584098059507582942883917511226",
                "328299363384410295763884869006539661562",
                "113803501980142141196269119362031329675",
                "244647404035860198967322688899819607806",
                "19240269759446072652502041473946465172"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/connection.h"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-95364bbc",
        "digest": {
            "length": 856.0,
            "function_hash": "174818639193327642443409448044413801833"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c",
            "function": "destroy_previous_session"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-a5e205a3",
        "digest": {
            "length": 1181.0,
            "function_hash": "166258855410913138801266803317107526426"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_session_logoff"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-a60beb6f",
        "digest": {
            "length": 5355.0,
            "function_hash": "141749231558801172115546232139565089353"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_sess_setup"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-a7f397de",
        "digest": {
            "line_hashes": [
                "297004126756288227908285474675522726703",
                "268659658837504198401863032526307706032",
                "296624723961167180803562079528672614966",
                "305992643832729861349185135912817091989",
                "237716553558632709093956764661326776463",
                "330562563618925551574172467480594720498",
                "283338264937735944827811546257209429354",
                "105309349186937946931560644591162732123",
                "207897301114757964331025186930230631017",
                "188280945983518673268505405196069810786",
                "327422833182963144665463407599434122618",
                "54690712854944189062554638213604010981",
                "267450405378082489665943207360784785230",
                "87180532630101454121491995230000699392",
                "195554818792450739061977712802667231779",
                "8404521866083984629593440128119862089",
                "99133310780563828978719478026243020695",
                "294218342844689681484611504057682437036"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/smb2pdu.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8eb243e670ecf30e91524dd12f7260dac07d335",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-c06d3f1d",
        "digest": {
            "length": 1152.0,
            "function_hash": "167923822034292053378373733097966088805"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_session_logoff"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cce57cd8c5dead24127cf2308fdd60fcad2d6ba6",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-c6982b7a",
        "digest": {
            "length": 5356.0,
            "function_hash": "91678965444341212030254614913153855375"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_sess_setup"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-ca0fb13e",
        "digest": {
            "line_hashes": [
                "40640551838881666992412891435356750114",
                "287445069216143970143252157146317153442",
                "272432220197545348692215718554704739346",
                "200796643468251471636356344036150090181",
                "114625347888109672118197518536968378968",
                "158215045584098059507582942883917511226",
                "328299363384410295763884869006539661562",
                "113803501980142141196269119362031329675",
                "244647404035860198967322688899819607806",
                "19240269759446072652502041473946465172"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/connection.h"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-cf07e901",
        "digest": {
            "length": 301.0,
            "function_hash": "93556800727486564952528467828972704206"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "alloc_preauth_hash"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-d9bc64b1",
        "digest": {
            "line_hashes": [
                "40640551838881666992412891435356750114",
                "287445069216143970143252157146317153442",
                "272432220197545348692215718554704739346",
                "200796643468251471636356344036150090181",
                "114625347888109672118197518536968378968",
                "158215045584098059507582942883917511226",
                "328299363384410295763884869006539661562",
                "113803501980142141196269119362031329675",
                "244647404035860198967322688899819607806",
                "19240269759446072652502041473946465172"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/connection.h"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8eb243e670ecf30e91524dd12f7260dac07d335",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-e9dc4b08",
        "digest": {
            "length": 856.0,
            "function_hash": "174818639193327642443409448044413801833"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/mgmt/user_session.c",
            "function": "destroy_previous_session"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-f31b9257",
        "digest": {
            "length": 301.0,
            "function_hash": "93556800727486564952528467828972704206"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "alloc_preauth_hash"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-f4ef8720",
        "digest": {
            "length": 1152.0,
            "function_hash": "167923822034292053378373733097966088805"
        },
        "signature_type": "Function",
        "target": {
            "file": "fs/smb/server/smb2pdu.c",
            "function": "smb2_session_logoff"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-f83b5e90",
        "digest": {
            "line_hashes": [
                "297004126756288227908285474675522726703",
                "268659658837504198401863032526307706032",
                "51448650403117895317813221185544537069",
                "289873519735553229074859803961269895940",
                "237716553558632709093956764661326776463",
                "130979960009992921730539082423788934756",
                "217046446482590909808361427330581534764",
                "249667312923185645835762253499634725836",
                "335881720498473020984678720935303353685",
                "335590987076451830758487913687396859075",
                "327422833182963144665463407599434122618",
                "54690712854944189062554638213604010981",
                "267450405378082489665943207360784785230",
                "87180532630101454121491995230000699392",
                "195554818792450739061977712802667231779",
                "8404521866083984629593440128119862089",
                "99133310780563828978719478026243020695",
                "294218342844689681484611504057682437036"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/smb2pdu.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2025-22037-f9396a9c",
        "digest": {
            "line_hashes": [
                "297004126756288227908285474675522726703",
                "268659658837504198401863032526307706032",
                "296624723961167180803562079528672614966",
                "305992643832729861349185135912817091989",
                "237716553558632709093956764661326776463",
                "330562563618925551574172467480594720498",
                "283338264937735944827811546257209429354",
                "105309349186937946931560644591162732123",
                "207897301114757964331025186930230631017",
                "188280945983518673268505405196069810786",
                "327422833182963144665463407599434122618",
                "54690712854944189062554638213604010981",
                "267450405378082489665943207360784785230",
                "87180532630101454121491995230000699392",
                "195554818792450739061977712802667231779",
                "8404521866083984629593440128119862089",
                "99133310780563828978719478026243020695",
                "294218342844689681484611504057682437036"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "target": {
            "file": "fs/smb/server/smb2pdu.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780",
        "signature_version": "v1",
        "deprecated": false
    }
]

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.6.107
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.23
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.11
Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.14.2